nnewkin/notes

nnewkin/notes

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH6.8 MEDIUM

app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, as demonstrated by an admin/?n=admin&c=index&a=doSaveSetup URI.